Privacy Policy
This policy explains what personal data TERABYX AI CORE LABS INDIA (OPC) PRIVATE LIMITED ("we") collects when you use PrismFilm AI Studio, why, who else processes it, how long we keep it, and how to have it deleted.
1. What we collect
Account
- Your name, email address and password. We store only a one-way hash of your password, never the password itself.
- When you last signed in and changed your password.
- Workspace details and, if you pay, billing name, billing email, address, state, country and GSTIN.
Your content
- Media you upload (video, audio, images), and what we make from it: previews, thumbnails, waveforms, renders and exports.
- Projects, timelines, captions, transcripts, translations and other project data.
- Voice consent recordings, if you record one (section 4).
Usage and security
- The jobs you run (for example transcription or renders), their logs and how many credits they used, attributed to you and your workspace.
- An audit log of security-relevant actions (sign-ins, uploads, downloads, deletions, member and billing changes). It records the account, the action and a one-way hash of your IP address, not the IP address itself.
- Your IP address is used briefly to limit abusive requests and then discarded.
Cookies and browser storage
We use one essential cookie, cf_session, to keep you signed in (it expires after 12 hours by default). The app also keeps a few things in your browser's storage, such as upload progress so uploads can resume, the last project you opened, and unsaved drafts. We don't use advertising or analytics cookies. The editor loads its fonts from Google Fonts, so your browser contacts Google when you open the app.
2. How we use it
To run the service you asked for: store and process your content, run the tasks you start, bill you and send your tax invoices, keep accounts secure, send emails you need (invites, password resets and budget alerts), and meet legal obligations. We don't sell personal data and we don't use your content to train AI models.
3. Where it is stored and who processes it
Your media is encrypted at rest with a key for your workspace. Our servers currently run in the United States (Railway) and media is stored with Cloudflare R2; data may therefore be processed outside India. We share data only with providers that help us run the service, and only what each task needs:
- Cloudflare Workers AI: audio for transcription and consent checks; caption text for translation; text for English speech; prompts (which can include transcript text and project and file names) for the editing assistant, AI agents and chapters; prompts and optional reference images for image generation.
- Sarvam AI: caption text for translation, and text to be spoken in Indian languages.
- Replicate: prompts and optional reference images, when you generate images or video.
- GPU processing (our own workers or RunPod): a temporary decrypted copy of the media a task needs (for example audio for stem separation or speaker detection). It never receives your encryption keys, and the temporary copy is deleted when the task ends.
- Razorpay: payment and subscription details. We don't see or store your full card or UPI details.
- Brevo: your name and email address, to deliver our emails.
- Railway (hosting) and Cloudflare (storage): all of the above, stored on our behalf.
If a workspace owner configures a webhook, we send workspace events to the address they chose. We may disclose data when the law requires it.
4. Voice consent recordings
Voice cloning, where it is offered, is only possible with a recorded statement in which the speaker names themselves and agrees. We keep the recording, encrypted, as evidence of consent and as the reference for the cloned voice, and we record a fingerprint (SHA-256 hash) of it in the audit log with the statement and each use. The speaker can withdraw consent at any time; cloning stops immediately. After consent is withdrawn and the voice profile is deleted, the recording itself can be deleted; the audit entries (including the fingerprint) remain as a record that consent existed and was withdrawn.
5. How long we keep it
- Your content is kept until you delete it or ask us to delete your account. Deleting a file removes it and everything made from it from storage. Deleting a project removes the project (and its Shorts) but not the media files, which you delete separately.
- Password reset links expire after 60 minutes; invites after 7 days.
- Tax invoices and payment records are kept for as long as Indian tax law requires, even after an account is deleted.
- The audit log cannot be edited or deleted, so its entries (which include the email address of the person who acted) are kept as a security and legal record.
6. Deleting your data and your rights
You can delete files, projects, voice profiles, members and API keys yourself in the app. To delete your whole account or a workspace you own, or to get a copy of your personal data, correct it or withdraw consent, write to our contact page from the email address on your account. We'll confirm your request and complete it within 30 days, except for the records we must keep (section 5). You can also complain to the Data Protection Board of India once it accepts complaints.
7. Security
Media is encrypted at rest with a key per workspace; access is controlled by workspace roles and checked again by the database; passwords, API keys and invite links are stored only as hashes; and security-relevant actions are recorded in an append-only audit log. No system is perfectly secure: we'll notify you and the authorities as the law requires if a breach affects your data.
8. Children
PrismFilm AI Studio is not meant for children. You must be 18 or older to create an account, or have the consent of a parent or guardian as required by law.
9. Changes
We'll post changes here and tell account holders by email about important ones before they take effect.
10. Contact
TERABYX AI CORE LABS INDIA (OPC) PRIVATE LIMITED: our contact page.